← Back

CVE-2017-11156

nvd nist
Published: Aug 14, 2017Modified: May 13, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows remote authenticated users to execute arbitrary code by uploading an executable via unspecified vectors.

Affected (33)

1 product
Download Station
Configuration A
33 vulnerable
Vulnerable SoftwareAffected Versions
Synology
Version 3.2-2295
Version 3.3-2382
Version 3.3-2383
Version 3.3-2386
Version 3.4-2477
Version 3.4-2478
Version 3.4-2480
Version 3.4-2485
Version 3.4-2486
Version 3.4-2489
Version 3.4-2490
Version 3.4-2514
Version 3.4-2555
Version 3.4-2557
Version 3.4-2558
Version 3.5-2638
Version 3.5-2705
Version 3.5-2706
Version 3.5-2955
Version 3.5-2956
Version 3.5-2962
Version 3.5-2963
Version 3.5-2967
Version 3.5-2968
Version 3.5-2970
Version 3.5-2973
Version 3.5-2980
Version 3.5-2982
Version 3.8.0-3416
Version 3.8.1-3420
Version 3.8.2-3455
Version 3.8.3-3458
Version 3.8.4-3468

References (2)

Timeline

No history available yet.